Kevin Ostrin
Director of Application/Product Security | Specializing in Application and Infrastructure Security | Building and Leading High Performing Security Teams | Secure Code Development | OSCE, OSCP, CISSP
- Role
- Director of Application and Product Security at Aon
- Location
- Lehi, UT, US
- LinkedIn followers
- 500 followers
About Kevin Ostrin
Seasoned security leader with over 11 years of dedicated experience in cybersecurity, with a proven ability to spearhead organization-wide security initiatives, integrating security principles into product lifecycles and infrastructure roadmaps. Demonstrated ability to grow and foster high-performing Penetration Testing/Offensive Security teams. Adept at collaborating with diverse cross-functional teams to drive technical and non-technical security strategies. Skilled in mentoring, motivating, and managing multinational teams, with a commitment to continual improvement and innovation in the cybersecurity landscape. Accelerating vulnerability discovery and remediation before threat actors find them.
Experience
Director of Application and Product Security
Sep 2022 — Present · Remote, UT, US
Owning of organization-wide security assessments for Web Application Assessments, Mobile Assessments, Internal and External Network Assessments, Threat Actor Simulations, Cloud Assessments (AWS and Azure), Red/Purple Team Assessments, and Threat Modeling; resulting in a 40% decrease in external security incidents- Collaborated with leaders across infrastructure, product engineering, operations, and legal to integrate trust and security principles throughout the product lifecycle (SDLC)- Leveraged risk assessments to provide strategic direction to integrate security into software lifecycles, infrastructure roadmaps, and developer security training opportunities- Designed and implemented security strategies that align with business objectives, KPIs, industry best practices, and threat intelligence trends- Utilized threat intelligence trends and aligned assessment methodologies with MITRE ATT & CK and NIST 800-115 to emulate adversarial assessments against organization-wide security controls- Developed and delivered security maturity and risk exposure reports to executive leadership using tailored dashboards and KPIs- Redesigned assessment policy, processes, and methodologies, increasing productivity by 81% and identifying 34% more high-risk vulnerabilities per assessment- Developed metrics and analytics that identify key performance drivers, strategies, and opportunities for team enhancements- Lead the security initiative to mature vulnerability management policies and procedures- Lead the security assessment of multiple AI features (LLMs)- Delivered offensive security recommendations for 20+ organization wide incidents assisting with triage and leading remediation validation- Launched the vulnerability disclosure program (bug bounty), and DAST/SAST/SCA SDLC integration program- Manage, mentor, and motivate 10 multi-national team members- Created service offerings a methodologies for 6 new assessment types
Education
Western Governors University
Master of Business Administration - MBA, Information Technology
Brigham Young University
Bachelor of Science (BS), Computer Science
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.